CVE-2018-11427

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
03/07/2019
Last modified:
10/07/2019

Description

CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to perform CSRF attacks on the device administrator.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:moxa:oncell_g3150-hspa_firmware:*:*:*:*:*:*:*:* 1.4 (including)
cpe:2.3:h:moxa:oncell_g3150-hspa:-:*:*:*:*:*:*:*
cpe:2.3:o:moxa:oncell_g3150-hspa-t_firmware:*:*:*:*:*:*:*:* 1.4 (including)
cpe:2.3:h:moxa:oncell_g3150-hspa-t:-:*:*:*:*:*:*:*